[SDP 3][e1c48c54-07f6-4290-9e4f-ae7651c003a4] Windows Small Business Server 2011, Windows Server 2012 Essentials, and the Windows Server Essentials Experience role diagnostics

Applies to: Windows Small Business Server 2011 StandardWindows Small Business Server 2011 EssentialsWindows Server 2012 Essentials

Summary


The Windows Small Business Server (SBS) 2011, Windows Server 2012 Essentials, and the Windows Server Essentials Experience role all-purpose data collection and analysis manifest collects and analyzes information that is used in troubleshooting Windows SBS 2011 and Windows Server 2012 Essentials issues. This includes general Windows issues in different technologies that include setup, performance, networking, and directory services. Additionally, data about Microsoft Exchange, Microsoft SQL Server, and Microsoft SharePoint is collected and analyzed. The collection and analysis are based on rules that were created to address common issues that may be affecting the server. These rules are updated regularly.

When you open a new case, you may receive an automated email message that contains instructions on how to generate and upload this manifest. We highly recommend that you complete this task at your earliest convenience, because the information that is collected can lead (and does lead in a good number of instances) to a faster resolution of the associated case. You may also receive a request to do this from the support engineer who is working on your case.

More Information


This article describes the information that may be collected from a computer when the Windows Small Business Server 2011 Standard all-purpose data collection and analysis manifest is running.

Information that is collected

Event logs - general
DescriptionFile name
Event log – Application – text, csv, and evtx formats<Computername>_evt_Application.*
Event log – System – text, csv, and evtx formats<Computername>_evt_System.*
Event log – Backup – format<Computername>_WindowsBackupEvtx.zip
Event logs – other<Computername>_evt_*.*

File version information
DescriptionFile name
File version information from %windir%\cluster\*.*<Computername>_sym_Cluster.*
File version information from %windir%\system32\*.dll<Computername>_sym_System32_dll.*
File version information from %windir%\system32\*.exe<Computername>_sym_System32_exe.*
File version information from %windir%\system32\*.sys<Computername>_sym_System32_sys.*
File version information from %windir%\system32\drivers folder<Computername>_sym_Drivers.*
File version information from %windir%\system32\drivers\*.*<Computername>_sym_SysWOW64_sys.*
File version information from {Program Files (x86}}\*.sys<Computername>_sym_ProgramFilesx86_sys.*
File version information from {Program Files}\*.sys<Computername>_sym_ProgramFiles_sys.*
File version information from {Program Files}\Microsoft iSNS Server\*.* and %windir%\system32\iscsi*.*<Computername>_sym_MS_Iscsi.*
File version information from all drivers that are currently running on the computer<Computername>_sym_RunningDrivers.*
File version information from all processes that are currently running on the computer<Computername>_sym_Process.*
File version information from print spooler folder %windir%\system32\Spool\*.*<Computername>_sym_PrintSpooler.*
File version information from Windows\Cluster<Computername>_sym_Cluster.*

Device and drivers
DescriptionFile name
Devices and connection information that is generated by devcon utility<Computername>_Devcon.log
Minifilter drivers enumeration that is generated by Fltmc.exe utility<Computername>_Fltmc.txt
MS-DOS device names that is generated by dosdev utility<Computername>_DosDev.txt
Output from Driver Verifier Manager (verifier.exe) utility<Computername>_Verifier.txt
Upper and lower filters information that is generated by fltrfind.exe utility<Computername>_FltrFind.txt
Information about driver signature that is generated by driverquery.exe<Computername>_SignedDrivers.txt

Storage/disk information
DescriptionFile name
Fibre Channel Information Tool information that is generated by FCInfo utility<Computername>_fcinfo.txt
Information from computer disk sectors that is generated by SecInspect.exe utility<Computername>_Secinspect.txt
iSCSI-related information that is generated by iscsicli.exe utility<Computername>_iSCSIInfo.txt
Parsing of storage-related event logs (Events 6 7 9 11 15 50 51 57 and 389) on System log that are generated by evparse.exe utility<Computername>_StorageEventLogs.htm
Fibre Channel Information tool (fcinfo) output to obtain SAN resources and configuration information<Computername>_FCInfo.txt
Dispart's SAN policy information<Computername>_DiskpartSANPolicy.txt

Memory dump files and related information
DescriptionFile name
Information about computer memory dumps, user memory dumps, and memory dump configuration<Computername>_DumpReport.*
Compressed version of mini computer memory dumps that is located at %windir%\minidumps<Computername>_dmp_*.cab
Windows Error Reporting mini-dumps that were generated in the past 30 days<Computername>_dmp_*.cab


Hotfixes and updates
DescriptionFile name
Installed updates/hotfixes<Computername>_Hotfixes.*


Virtualization
DescriptionFile name
Basic information about computer virtual environment<Computername>_Virtualization.*


Networking-related information
DescriptionFile name
Basic IP networking configuration information, such as TCP/IP registry key, ipconfig, netstat, nbtstat, and netsh output<Computername>_TcpIp-Info.txt
Basic SMB configuration information that is based on output of net.exe utility<Computername>_SMB-Info.txt
Information about TCP Offload from the registry and netsh<Computername>_TCPIP-Info-Offload.txt
Networking setup / information about attempts to join domains<Computername>_netsetup.log
Network diagnostic took (netdiag.exe) output<Computername>_netdiag.txt
Permissions dump for registry key HKLM\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg<Computername>_winreg.txt
DNS cache information from ipconfig.exe /displaydns command<Computername>_DnsClient-DnsCache.txt
Hosts file from \Windows\System32\Drivers\etc. folder<Computername>_DnsClient-HostsFile.txt
Services file from \Windows\System32\Drivers\etc. folder<Computername>_TCPIP-ServicesFile.txt
Lmhosts file from \Windows\System32\Drivers\etc. folder<Computername>_WinsClient-LmhostsFile.txt
Firewall information from "netsh firewall" context output<Computername>_Firewall-Netsh-Fw.txt
IPsec information from "netsh ipsec" context output<Computername>_IPsec-Netsh.txt
IPsec policy information through "netsh ipsec static exportpolicy" output<Computername>_IPsec-Export.ipsec
General networking configuration from "netsh dump" output<Computername>_Netsh-Dump.txt
Load-balancing configuration through wlbs.exe display command<Computername>_NLB-WlbsDisplay.txt
Remote Access Service information through "netsh ras" context output<Computername>_RAS-Netsh.txt
General IPv4 information through "netsh int ipv4" context output<Computername>_TCPIP-Netsh-IPv4.txt
General IPv6 information through "netsh int ipv6" context output<Computername>_TCPIP-Netsh-IPv6.txt
Winsock catalog information through "netsh winsock show catalog" output<Computername>_WinSock-Netsh.txt
Wired 802.1X (LAN) information through "netsh lan" context output<Computername>_8021x-Netsh-LAN.txt
Wireless Local Area Network (WLAN) 802.11 connectivity and security settings through "netsh wlan" context output<Computername>_8021x-Netsh-WLAN.txt
Background Intelligent Transfer Service (BITS) information through "BitsAdmin /list" command output<Computername>_BITS-BitsAdmin-List.txt
Dynamic Host Configuration Protocol (DHCP) Server information through "netsh dhcp server" context output<Computername>_DhcpServer-Netsh.txt
Windows Internet Name Service (WINS) server information through "netsh wins server" context output<Computername>_WinsServer-Netsh.txt
Windows Internet Name Service (WINS) client – Netbios cache through "nbtstat.exe –c" command output<Computername>_WinsClient-NetbiosCache.txt
Remote procedure call (RPC) general information through "netsh rpc" context output<Computername>_RPC-Netsh.txt
Displays the current Windows HTTP Services (WinHTTP) proxy information through "netsh winhttp show proxy" output<Computername>_WinHttp-Netsh.txt


Printers and print drivers
DescriptionFile name
Printers and print driver information. This includes drivers, print monitors, and print processors.<Computername>_PrintInfo.*


Directory Services-related information
DescriptionFile name
Netlogon service log file (\Windows\Debug\Logs\netlogon.log)<Computername>_Netlogon.log
Winlogon log file (\Windows\security\logs\winlogon.log)<Computername>_Winlogon.log
Security templates that are currently cached on the system (From \Windows\Security\Templates\Policies)<Computername>_AppliedSecTempl.txt
Collects user rights settings by using the showpriv.exe tool<Computername>_Userrights.txt
Networking setup / domain join-related information<Computername>_Netsetup.log


Registry keys
DescriptionFile name
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Hotfix

HKCU\SOFTWARE\Policies\Microsoft

HKLM\Software\Policies\Microsoft

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer

HKLM\SYSTEM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

HKLM\Software\Microsoft\Active Setup

HKCU\Software\Microsoft\Active Setup

HKLM\Software\Microsoft\Windows NT\CurrentVersion

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions

HKLM\SYSTEM\CurrentControlSet\Control\ProductOptions

HKCU\Software\Microsoft\Windows NT\Currentversion\AppCompatFlags

HKCU\Software\Microsoft\Java VM

HKLM\Software\Microsoft\Windows\CurrentVersion\NetCache

HKLM\Software\Microsoft\EAPOL\Parameters\General\Global

HKLM\Software\Microsoft\NetworkAccessProtection

HKLM\Software\Microsoft\Windows NT\CurrentVersion\NetworkList
<Computername>_reg_Software.txt
HKLM\System\MountedDevices

HKLM\Hardware\DESCRIPTION\System\CentralProcessor

HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider

HKLM\System\CurrentControlSet\Control\Session Manager\Power

HKLM\SYSTEM\CurrentControlSet\Control\Lsa

HKLM\System\CurrentControlSet\Control\Session Manager

HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation

HKLM\SYSTEM\CurrentControlSet\Control\Video

HKLM\System\CurrentControlSet\Services\napagent

HKLM\System\CurrentControlSet\Services\Afd

HKLM\System\CurrentControlSet\Services\BITS

HKLM\System\CurrentControlSet\Services\Dhcp

HKLM\System\CurrentControlSet\Services\DHCPServer

HKLM\System\CurrentControlSet\Services\Dnscache

HKLM\System\CurrentControlSet\Services\DNS

HKLM\System\CurrentControlSet\Services\IPsec

HKLM\System\CurrentControlSet\Services\PolicyAgent

HKLM\System\CurrentControlSet\Services\lanmanserver

HKLM\System\CurrentControlSet\Services\LanmanWorkstation

HKLM\System\CurrentControlSet\Services\MpsSvc

HKLM\System\CurrentControlSet\Services\MRxDav

HKLM\System\CurrentControlSet\Services\WebClient

HKLM\System\CurrentControlSet\Services\MrxSmb

HKLM\System\CurrentControlSet\Services\MrxSmb10

HKLM\System\CurrentControlSet\Services\MrxSmb20

HKLM\System\CurrentControlSet\Services\rdbss

HKLM\System\CurrentControlSet\Services\MUP

HKLM\System\CurrentControlSet\Services\NetBT

HKLM\System\CurrentControlSet\Services\Netlogon

HKLM\System\CurrentControlSet\Services\RasMan

HKLM\System\CurrentControlSet\Services\SharedAccess

HKLM\System\CurrentControlSet\Services\wscsvc

HKLM\System\CurrentControlSet\Services\SMB

HKLM\System\CurrentControlSet\Services\Tcpip

HKLM\System\CurrentControlSet\Services\Tcpip6

HKLM\System\CurrentControlSet\Services\VSS

HKLM\System\CurrentControlSet\Services\Winsock

HKLM\System\CurrentControlSet\Services\Winsock2
<Computername>_reg_System.txt
HKLM\System\MountedDevices<Computername>_reg_MountedDevices.hiv
HKCU\Network<Computername>_reg_NetworkConnections.TXT
HKLM\System\CurrentControlSet\Control\CrashControl

HKLM\System\CurrentControlSet\Control\Session Manager

HKLM\System\CurrentControlSet\Control\Session Manager\Memory Management

HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

HKLM\Software\Microsoft\Windows\Windows Error Reporting

HKLM\Software\Policies\Microsoft\Windows\Windows Error Reporting
<Computername>_reg_Recovery.txt
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Runonce

HKCU\Software\Microsoft\Windows\CurrentVersion\RunonceEx

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKLM\ Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\Runonce

HKLM\Software\Microsoft\Windows\CurrentVersion\RunonceEx

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad"

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Load

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\UserInit
<Computername>_reg_Startup.txt
HKLM\SYSTEM\CurrentControlSet\Control\Print<Computername>_reg_Print.*
HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server Web Access

HKLM\System\CurrentControlSet\Services\TermService

HKLM\System\CurrentControlSet\Services\TermDD
<Computername>_reg_TermServer.txt
HKLM\Software\Microsoft\Internet Explorer

HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings

HKCU\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings

HKLM\Software\Microsoft\Internet Domains

HKLM\Software\Microsoft\Internet Connection Wizard

HKCU\Software\Microsoft\Internet Connection Wizard

HKLM\Software\Microsoft\Internet Account Manager

HKCU\Software\Microsoft\Internet Account Manager

HKLM\Software\Microsoft\IEAK

HKCU\Software\Microsoft\IEAK

HKLM\Software\Microsoft\IEAK6

HKLM\Software\Microsoft\IE Setup
<Computername>_reg_IE.txt
HKLM\System\CurrentControlSet\Services\iScsiPrt

HKLM\Software\Microsoft\iSCSI Target

HKLM\Software\Microsoft\Windows NT\CurrentVersion\iSCSI
<Computername>_reg_iSCSI.*
HKLM\Software\Microsoft\iSCSI Target<Computername>_reg_iSCSI_Target.hiv
HKLM\Software\Microsoft\Windows NT\CurrentVersion\iSCSI<Computername>_reg_CurrentVersion_iSCSI.HIV
HKLM\System\CurrentControlSet\Control\MPDev

HKLM\System\CurrentControlSet\Control\iSCSIPrt

HKLM\System\CurrentControlSet\Services\MSiSCSI

HKLM\System\CurrentControlSet\Services\MSDsm

HKLM\System\CurrentControlSet\Services\MPIO

HKLM\System\CurrentControlSet\Control\Class\{4d36e97b-e325-11ce-bfc1-08002be10318}

HKLM\System\CurrentControlSet\Services\Tcpip
<Computername>_reg_Storage.txt
HKLM\Software\Microsoft\Exchange

HKLM\System\CurrentControlSet\Services\MSExchangeActiveSyncNotify

HKLM\System\CurrentControlSet\Services\MSExchangeADDXA

HKLM\System\CurrentControlSet\Services\MSExchangeAL

HKLM\System\CurrentControlSet\Services\MSExchangeDSAccess

HKLM\System\CurrentControlSet\Services\MSExchangeES

HKLM\System\CurrentControlSet\Services\MSExchangeFBPublish

HKLM\System\CurrentControlSet\Services\MSExchangeIS

HKLM\System\CurrentControlSet\Services\MSExchangeMGMT

HKLM\System\CurrentControlSet\Services\MSExchangeMTA

HKLM\System\CurrentControlSet\Services\MSExchangeMU

HKLM\System\CurrentControlSet\Services\MSExchangeOMA

HKLM\System\CurrentControlSet\Services\MSExchangeSA

HKLM\System\CurrentControlSet\Services\MSExchangeSenderID

HKLM\System\CurrentControlSet\Services\MSExchangeSRS

HKLM\System\CurrentControlSet\Services\MSExchangeTransport

HKLM\System\CurrentControlSet\Services\MSExchangeUCF

HKLM\System\CurrentControlSet\Services\MSExchangeWEB

HKLM\Software\Microsoft\MosTrace\CurrentVersion\DebugAsyncTrace

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\STORE.EXE
<Computername>_reg_Exchange.txt
HKLM\Cluster<Computername>_reg_Cluster.hiv
HKLM\System\CurrentControlSet\Services\Clussvc<Computername>_reg_Clussvc.txt
HKLM\System\CurrentControlSet\Services\Clusdisk<Computername>_reg_Clusdisk.txt


Domain controllers
DescriptionFile name
Domain Controller Diagnostics Tool (dcdiag.exe) output<Computername> _DCDiag.txt
Replication topology overview through "repadmin.exe /showrepl" output<Computername>_repadmin.txt


Other
DescriptionFile name
Resultant Set of Policy (RSoP) that is generated by gpresult.exe utility<Computername>_GPResult.*
Schedule Tasks information (csv and txt) that is generated by schtasks.exe utility<Computername>_schtasks.*
System Information - MSInfo32 tool output – txt and nfo formats<Computername>_msinfo32.*
Volume Shadow Copy Service (VSS) information<Computername>_VSSAdmin.txt
Windows basic activation information through %windir%\system32\slmgr.vbs<Computername>_KMSActivation.txt
Operating system restart options file (Boot.ini)<Computername>_BOOT.INI
Hyperthread-capable processor information<Computername>_HyperThread.txt
Information about process and threads collected by the pstat.exe tool<Computername>_PStat.txt
SP Catalog logging file (Windows\System32\catroot2 \DBErr.txt)<Computername>_DBErr.txt
Windows Update Reporting Events log file (from Windows\SoftwareDistribution)<Computername>_ReportingEvents.log
Windows Update log file (from Windows folder)<Computername>_WindowsUpdate.log
List Performance information from top processes, such as memory usage, handle count, and number of threads, and also from kernel memory allocation information<Computername>_ProcessPerfInfo.*


Windows Vista or Windows Server 2011

Hyper-V role
DescriptionFile name
Event log - Hyper-V related event logs (Microsoft-Windows-Hyper-V*) – Text, csv and evtx formats<Computername>_evt_HyperV*.*
Hyper-V configuration and virtual machine information<Computername>_HyperV-Info.htm
Hyper-V virtual machine definition files from %ProgramData%\Microsoft\Windows\Hyper-V\Virtual Machines\*.xml<Computername>_{VirtualMachineGUID}.xml


Server manager/roles information
DescriptionFile name
Information about server roles that are installed on a server and generated by servermanagercmd.exe<Computername>_ServerManagerCmdQuery.*
Server manager log file that is located at %windir%\logs\ServerManager.log<Computername>_ServerManager.log


Boot information
DescriptionFile name
Output from bcdedit.exe utility<Computername>_BCDEdit.txt

<Computername>_BCD-Backup.bak


Deployment logs
DescriptionFile name
Setupact.log from the following folders:

%windir%

%windir%\Panther

%windir%\Panther\UnattendedGC
<Computername>_Setupact-*.log
Setupapi logs from the %windir%\inf folder<Computername>_SetupApi.app.log

<Computername>_SetupApi.evt.log

<Computername>_SetupApi.offline.log
Setuperr.log file from the Windows folder<Computername>_Setuperr.log
Upgrade log – SetupReport.txt from the Windows\panther folder<Computername>_SetupReport.txt


Servicing logs
DescriptionFile name
Component-Based Servicing logs from %windir%\Logs\CBS<Computername>_CBS*.log
DPX Setup Act log from %windir%\logs\DPX<Computername>_setupact.log"
Pending Operations Queue Exec log from %windir%\winsxs<Computername>_poqexec.log
Windows Side-by-Side Pending Bad log from %windir%\ winsxs<Computername>_pending.xml.bad
Windows Side-by-Side Pending log from %windir%\ winsxs<Computername>_pending.xml


ServerCore installation option media
DescriptionFile name
Installed roles and component (output from oclist.exe command)<Computername>_OCList*.log
Windows Update, Remote Desktop, and other information that is configured by scregedit.wsf script<Computername>_Scregedit.txt


Domain controllers
DescriptionFile name
Domain controller promotion debug log from the \Windows\debug folder<Computername>_DCPromo.log


Networking-related information
DescriptionFile name
Networking Setup/ information about attempts to join domains<Computername>_netsetup.log
Current configuration settings for Network Access Protection (NAP) through "netsh nap client export" command<Computername>_NapClient-Export.xml
Network Access Protection (NAP) client information through "netsh nap client" context output<Computername>_NapClient-Netsh.txt
Windows Firewall with Advanced Security general information through "netsh advfirewall show" context output<Computername>_Firewall-Netsh-AdvFw.txt
Windows Firewall with Advanced Security computer security connection rules through "netsh advfirewall consec" context output<Computername>_Firewall-Netsh-AdvFw-ConSec-Rules.txt
Windows Firewall with Advanced Security firewall rules through "netsh advfirewall firewall" context output<Computername>_Firewall-Netsh-AdvFw-Fw-Rules.txt
Information about current Firewall policy through "netsh advfirewall export" command<Computername>_Firewall-Netsh-AdvFw-Export.wfw
HTTP service information through "netsh http" context output<Computername>_Http-Netsh.txt
Network Input Output (NETIO) binding filters through "netsh netio show bindingfilters" command<Computername>_TCPIP-Netsh-NetIO.txt


Windows SBS logs
DescriptionFile name
Windows SBS logs
Exchange Server setup logs
DcPromo logs
<Computername>_*.log

Windows SBS BPA
DescriptionFile name
Windows SBS 2011 Std BPA data that is captured by using the latest BPA configuration file<Computername>_BPA.xml
Windows SBS Autodiscover Troubleshooter
DescriptionFile name
Windows SBS 2011 Std Exchange Autodiscover configuration <Computername>_AutodiscoverTroubleshooter.txt


More information

In addition to the files that are collected and listed earlier, this SDP manifest can detect one or more of the following situations:
  • Whether the computer is running in a virtual environment
  • Presence of a computer memory dump in the past 30 days 
  • Presence of a user mode memory dump in the past 30 days 
  • Problems that are related to a computer memory dump configuration that could avoid a memory dump being generated 
  • Presence of services that could interfere with memory dump generation 
  • Unexpected Shutdown event logs on System log from the past 30 days (Events 50 from EventLog) 
  • Computer memory dump-related event logs on the System log from the past 30 days (Events 1001 from Save Dump) 
  • SRV-related event logs 2020 and 2021 from the past 30 days 
  • Processes that have lots of handles (more than 40,000 handles) 
  • Computer that has a low number of system page entries (less than 5,000) 
  • Computer in low available memory condition (computer-committed limit greater than 85 percent) 
  • Any kernel pool memory tag that is using more than 60 percent of all allocated memory 
  • Unsupported version of a service pack 
  • Unsupported operating system versions

References

For more information, click the following article number to view the article in the Microsoft Knowledge Base:
973559 Frequently asked questions about the Microsoft Support Diagnostic Tool (MSDT) for Windows 7